This method must have the support of the free programs provided on the network such as ProcessExplorerNt, Autoruns. These are the two main tools supported by Microsoft for Windows operating system users.
First, download the two software to your computer.
ProcessExplorerNt: this program aims to stop the operation of the virus file is running.
After downloading ProcessExplorer.zip from Microsoft home page, you unzip this folder and run the file procexp.exe.
The window that appears shows the files running on the computer. The observing operation on the list is the most important to discover strange files that are not part of the operating system. They often have signs such as strange symbols such as girls, skulls . even a folder image (the directory principle for organizing files that cannot be run).
You right-click on the strange file and select Kill Process . After this step, we switch to the second tool, Autoruns.
Autoruns
Viruses are usually installed on the operating system to automatically activate each time the machine starts up. This tool is effective for disabling these autorun files.
As above, we run the file autoruns.exe and look in the list of strange boot files and remove the v in the leading square.
Removal of virus does not need specialized software Picture 1
Autorun window interface.
Combining this software, you can also go to the Registry to destroy suspicious boot files that are malicious code.
From the Start menu select Run and type "regedit". Go to the Registry window pane and follow the directory tree to find the path:
In the right column list, the files that start with Windows will appear. Select the strange file and press " delete " and close the window.
In some cases, the virus prevents you from entering the Registry, so you can do it later.
First, go to Start - Run and type " cmd " to enter the Command Line window. Then, type the following line to reopen the functionality into the Registry.
REG add HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem / v DisableRegistryTools / t REG_DWORD / d 0 / f
The screen displays the message "The operation complete successfully" is okay.